GeoQR Subprocessors
Last updated on August 20, 2026.
This page lists providers that may process Customer Personal Data for GeoQR under the Data Processing Addendum. A provider may also process other information as an independent controller under its own terms, particularly for billing or optional analytics.
Cloudflare, Inc.
Purpose: edge and Worker hosting, queues, object storage, networking, DNS and certificate operations, custom hostnames, database connectivity, security, Turnstile, and operational logs.
Data: Customer Content, domain configuration, resolver requests, application requests, security data, and operational metadata.
Location and transfers: global infrastructure, including processing outside the EEA, subject to Cloudflare's data-processing terms and applicable transfer safeguards.
Supabase, Inc.
Purpose: managed PostgreSQL database infrastructure.
Data: account and workspace references, Customer Content, QR and resolver configuration, analytics records, and operational data stored in the application database.
Location and transfers: processing may occur in the EEA and other locations under Supabase's data-processing terms and applicable transfer safeguards.
Vercel Inc.
Purpose: hosting and delivery of the GeoQR web and marketing applications.
Data: web requests, application delivery metadata, and information submitted through hosted web interfaces before it is sent to the GeoQR API.
Location and transfers: global infrastructure, including processing outside the EEA, subject to Vercel's data-processing terms and applicable transfer safeguards.
Resend, Inc.
Purpose: transactional and support-related email delivery.
Data: recipient email addresses, message content, and delivery metadata.
Location and transfers: processing may occur outside the EEA under Resend's data-processing terms and applicable transfer safeguards.
Google LLC
Purpose: destination URL safety checks through Google Web Risk. Optional public-site analytics are governed separately by the Privacy Policy and the visitor's consent choice.
Data: configured destination URLs submitted for safety classification and associated request metadata.
Location and transfers: global infrastructure, including processing outside the EEA, subject to Google's data-processing terms and applicable transfer safeguards.
Changes and Objections
GeoQR will notify the Customer account contact at least 30 days before a new or replacement subprocessor begins processing Customer Personal Data. If urgent security or legal circumstances make advance notice impossible, GeoQR will provide notice as soon as legally and practically possible. Customers may object on reasonable data-protection grounds as described in the DPA.
Questions about this list may be sent to info@geoqr.io.